CRITICAL🇵🇱 Wersja polska

CVE-2026-8401

CVSS 9.8pub. 2026-05-12upd. 2026-06-30

Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.

🤖 AI Analysis
How it works

The error classified as CWE-693 (Protection Mechanism Failure) indicates the ineffectiveness of the protection mechanism — in this case the sandbox. An attacker can exploit the vulnerability in the Profile Backup component to escape from the restricted browser execution environment. The attack can be conducted remotely, without authentication and without any user interaction, which makes it particularly dangerous.

Impact

Successful exploitation of the vulnerability allows an attacker to escape from the browser sandbox, which may lead to obtaining unauthorized access to the operating system, violating data confidentiality and integrity, and destabilizing system operation.

Mitigation & patch

The software must be immediately updated to Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11 or Thunderbird 140.11, in which the vulnerability has been patched by the vendor.

Who is affected

Mozilla Firefox in versions before 150.0.3, Mozilla Firefox ESR in versions before 115.36 and before 140.11, Mozilla Thunderbird in versions before 140.11.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Mozilla Firefox

    APP
    Mozilla
    < 150.0.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-9680CRITICAL9.8⚠ KEVPL ✓same product

Use-after-free w Animation timelines Firefox/Thunderbird — RCE

CVE-2022-26486CRITICAL9.6⚠ KEVPL ✓same product

Use-after-free w WebGPU IPC framework Mozilla — sandbox escape

CVE-2019-11708CRITICAL10.0⚠ KEVPL ✓same product

Mozilla Firefox/Thunderbird: przełamanie sandbox przez IPC Prompt:Open

CVE-2010-3765CRITICAL9.8⚠ KEVPL ✓same product

RCE w Mozilla Firefox przez błąd nsCSSFrameConstructor::ContentAppended

CVE-2026-84119CRITICAL9.6same product

Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox...